XML Injection Vulnerability in TextPattern by TextPattern Inc.
CVE-2018-1000090
7.5HIGH
What is CVE-2018-1000090?
TextPattern version 4.6.2 includes a vulnerability in its Import XML feature that allows an attacker to perform XML Injection. By uploading a maliciously crafted XML file, an attacker could exhaust the web server's memory resources, leading to a denial of service. This vulnerability highlights the importance of validating and sanitizing XML input to prevent such attacks and safeguard server performance.
